related Recognised Industry Security Qualifications eg CCP, CISSP, CISM or similar (or able to achieve Proven experience of assessing and managing information risk in line with industry good practice (NIST, ISO 27001) Experience managing a team and working with customers ideally within a complex engineering or industrial setting Benefits: As well as a competitive pension scheme, BAE Systems also offers More ❯
related Recognised Industry Security Qualifications eg CCP, CISSP, CISM or similar (or able to achieve Proven experience of assessing and managing information risk in line with industry good practice (NIST, ISO 27001) Experience managing a team and working with customers ideally within a complex engineering or industrial setting Benefits: As well as a competitive pension scheme, BAE Systems also offers More ❯
Experience with scripting and automation using Python, Bash, or PowerShell. Certifications such as OSCP, OSCE, CEH, or similar are highly desirable. Understanding of regulatory compliance standards (ISO 27001, GDPR, NIST, etc.). Excellent problem-solving skills and attention to detail. Ability to communicate findings and recommendations effectively to clients. Why Join Darkshield? Work with a passionate and expert cybersecurity team. More ❯
Whetstone, Greater London, UK Hybrid / WFH Options
Deutsche Bank AG, Frankfurt am Main
Expertise in data analysis techniques, data visualization, and reporting is crucial Experience in delivering secure, scalable, and reusable architectures across complex environments Understanding of security frameworks (MITRE ATT&CK, NIST CSF, etc.) Deutsche Banks values define the working environment they strive to create diverse, supportive and welcoming of different views. They embrace a culture reflecting a variety of perspectives, insights More ❯
risk, and assurance. Key Responsibilities: 1. Governance, Risk & Compliance (GRC) Management Develop, implement, and maintain GRC policies, frameworks, and procedures aligned with industry standardsand regulatory requirements (ISO 27001, NIST, SOC 2, GDPR, HIPAA, PCI DSS). Conduct workshops to gather requirements for risk assessments and security reviews, ensuring risk mitigation strategies are in place. Maintain a risk register andMore ❯
London, South East, England, United Kingdom Hybrid / WFH Options
Precise Placements
preferred), and SOAR tools. Expertise in incident handling , threat analysis , and digital forensics . Scripting or automation experience (Python, PowerShell, etc.) is highly beneficial. Knowledge of MITRE ATT&CK , NIST CSF , and related security frameworks. Legal, financial, or similarly high-compliance industry experience is a bonus. Why Apply? Join a global firm with one of the most recognised names in More ❯
in effectively communicating with technical and non-technical roles. Strong project management skills with the ability to break down complex issues into actionable goals. Knowledge of cybersecurity frameworks (e.g., NIST, ISO) and privacy regulations (e.g., GDPR, HIPAA). Preference for certifications like CIPP-E, Security+, or CISSP. Benefits: Hybrid working model: up to 40% remote, with office days in London More ❯
Tracker * Optional failure remediation support to control owners Key Skills/Knowledge: * Knowledge of IT domain, IT control frameworks, IT related regulations. * Knowledge of control and regulatory frameworks (e.g. NIST, PS21/3, COBIT, DORA, etc.). * Analytical Skills * Ability to take a rigorous and methodical approach to IT control testing * Exceptional stakeholder management and communication skills to engage effectively More ❯
and using monitoring tools like Prometheus and Azure Monitor Proven track record managing Azure landing zones with enterprise governance and security controls Solid understanding of cloud security frameworks (CIS, NIST) and Azure tools like Key Vault, RBAC, and Defender for Cloud If you are interested in the DevOps Engineer role, please send an application detailing proof of the above or More ❯
Ideally, you'll have experience leading within a risk management role and havea good knowledge of methodologies such as IEC 62443 and ISO 27005. Knowledge ofcontrol frameworks such as NIST, IEC 62443, ISO 27001, ITIL (InformationTechnology Infrastructure Library), and SABSA is also required. You'll need to have a structured, methodical and accurate approach with theability to interpret relevant industry More ❯
Ideally, you'll have experience leading within a risk management role and havea good knowledge of methodologies such as IEC 62443 and ISO 27005. Knowledge ofcontrol frameworks such as NIST, IEC 62443, ISO 27001, ITIL (InformationTechnology Infrastructure Library), and SABSA is also required. You'll need to have a structured, methodical and accurate approach with theability to interpret relevant industry More ❯
Ideally, you'll have experience leading within a risk management role and havea good knowledge of methodologies such as IEC 62443 and ISO 27005. Knowledge ofcontrol frameworks such as NIST, IEC 62443, ISO 27001, ITIL (InformationTechnology Infrastructure Library), and SABSA is also required. You'll need to have a structured, methodical and accurate approach with theability to interpret relevant industry More ❯
threat monitoring, detection, and response using cloud-native security solutions such as Microsoft Defender, Sentinel, and SIEM platforms. • Ensure compliance with cloud security frameworks and regulatory requirements (ISO 27001, NIST, GDPR, SOC2, FCA). • Conduct regular security risk assessments, penetration tests, and vulnerability management across cloud services. • Oversee endpoint security, cloud network and API security for robust protection across all … Strong experience managing Microsoft 365 (Exchange, SharePoint, Teams), Azure cloud infrastructure, and security tools such as Microsoft Defender and Sentinel. • Security & Compliance: Deep knowledge of security frameworks (ISO 27001, NIST, CIS), compliance requirements (GDPR, SOC2), and risk management best practices. • Identity & Access Management (IAM): Expertise in Azure AD, MFA, Conditional Access, Single Sign-On (SSO), and Privileged Access Management (PAM More ❯
our office in Dudley (UK), we are currently recruiting a driven Cybersecurity & Compliance Manager. Position purpose The Cybersecurity & Compliance Manager will lead Tosca’s efforts to ensure adherence to NIST CFS 2.0, ISO 27001, and other standards. This role focuses on developing security protocols, maintaining documentation, conducting risk assessments, and ensuring regulatory compliance. Responsibilities include managing security infrastructure, incident response … and promoting cybersecurity awareness. The position requires collaboration with Global IT, cross-functional teams, and third-party partners. Key qualifications include experience in cybersecurity and compliance, strong knowledge ofNISTand ISO standards, risk management expertise, and effective communication skills. This is a full-time role based in Dudley, UK, with travel up to 30% of the time. Responsibilities Implement … security protocols and manage information security programs Report performance, exceptions, and outages to all audiences transparently. Align disaster recovery with business continuity plans. Ensure compliance with ISO27001, NIST CFS 2.0, and maintain ISMS. Identify risks, develop a comprehensive security plan. Test cyber-attacks regularly to address vulnerabilities. Monitor security trends, adapt strategies. Oversee incident monitoring, detection, response via SOC andMore ❯
planning, and performance metric tracking (e.g., velocity, burn-down charts). Advanced Cryptography : Understanding of cryptographic algorithms, protocols, and key management systems. Familiarity with PQC standardsand protocols (e.g., NIST PQC). Security Architecture : Expertise in designing and implementing secure architectures for software and cloud environments. Embedded Systems : Knowledge of secure software for embedded systems and IoT security. Software Security More ❯
holding one or more of the following: Professional membership with a recognised body, supported by externally validated evidence of professional development ISO/IEC 27001 Information Security Management - Foundation NIST Cyber Security Professional (NCSP) - Foundation Certificate ISO/IEC 27001 Information Security Management - Practitioner, Lead Implementer, or Lead Auditor More ❯
Bristol, Gloucestershire, United Kingdom Hybrid / WFH Options
QinetiQ Limited
of action The ability to understand how architects and designers employ technology to build systems of interest Digitally literate (including fluency in Microsoft Office tools) Able to understand relevant NIST frameworks and ISO27001 standardsand how to apply in practice Knowledge of MITRE ATT&CK Essential qualifications for the Cyber Security Risk Consultant: We value difference and we don't More ❯
Cheltenham, England, United Kingdom Hybrid / WFH Options
FR Secure
and secure-by-design principles. Familiarity with government and defence security standards such as: HMG/NCSC IA Policies and Guidelines JSP440 and other MoD IA standards Cyber Essentials NIST, NIS-D ONR SyAPs (Security Assessment Principles) Excellent stakeholder communication skills – you can clearly explain complex security concepts to both technical and non-technical audiences. Security Clearance eDV clearance is More ❯
systems Understanding of design and architecture principles, security controls, risk management and the relevant legal and regulatory requirements for Artificial Intelligence systems Familiar with standards such as ISO 42001, NIST AI RMF and regulation such as EU Artificial Intelligence Act Proficient in working with geographically dispersed or remote teams, demonstrating excellent technical writing proficiency and oral presentation skills Team player More ❯
through the delivery and operational life cycle of a system Provision of authoritative specialist security advice in Risk and threat-based mitigation to system designs Control frameworks such as NIST, ISO, CIS Protective monitoring, Authentication and authorization best practices. Develop excellent working relationships with key stakeholders, peers and subordinates. Communicating effectively verbally and in writing, demonstrated through: Effectively explain complex More ❯
projects across both banking and securities domains. Candidate profile: Strong experience delivering cybersecurity or technology projects in large-scale, regulated environments. Familiarity with security standards such as ISO 27001, NIST, PCI-DSS, FFIEC, or EBA ICT. Solid understanding of audit and risk remediation processes. Excellent stakeholder engagement and cross-functional collaboration skills. A background in managing multiple complex, high-impact More ❯
projects across both banking and securities domains. Candidate profile: Strong experience delivering cybersecurity or technology projects in large-scale, regulated environments. Familiarity with security standards such as ISO 27001, NIST, PCI-DSS, FFIEC, or EBA ICT. Solid understanding of audit and risk remediation processes. Excellent stakeholder engagement and cross-functional collaboration skills. A background in managing multiple complex, high-impact More ❯
Drive innovation and thought leadership within the Practice by defining standards, sharing knowledge, and mentoring peers Influence customer outcomes through expert knowledge of DevSecOps tools and compliance frameworks like NIST, CIS, SOC 2, and PCI DSS You'll travel to client sites across the UK, working directly with business and technical stakeholders to drive real business value What you'll More ❯
Drive innovation and thought leadership within the Practice by defining standards, sharing knowledge, and mentoring peers Influence customer outcomes through expert knowledge of DevSecOps tools and compliance frameworks like NIST, CIS, SOC 2, and PCI DSS You'll travel to client sites across the UK, working directly with business and technical stakeholders to drive real business value What you'll More ❯
Drive innovation and thought leadership within the Practice by defining standards, sharing knowledge, and mentoring peers Influence customer outcomes through expert knowledge of DevSecOps tools and compliance frameworks like NIST, CIS, SOC 2, and PCI DSS You'll travel to client sites across the UK, working directly with business and technical stakeholders to drive real business value What you'll More ❯